Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in zhopaorlaaato (PyPI)

zhopaorlaaato

Risk score

92

AI summary

Indexed incident for zhopaorlaaato (pypi).

Description

Package is runs an Infostealer targeting telegram and Discord credentials. Depending on version, the infostealer is either downloaded from an URL or embedded in the package


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-08-dsidelib

Reasons (based on the campaign):

  • infostealer

  • Downloads and executes a remote malicious script.

  • exfiltration-browser-data

  • target:telegram


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents